• magic_lobster_party@fedia.io
    link
    fedilink
    arrow-up
    39
    ·
    1 month ago

    One way this happened to me was because the ” choose password” page silently truncated too long passwords. The login page didn’t truncate.

    • helpImTrappedOnline@lemmy.world
      link
      fedilink
      arrow-up
      20
      ·
      30 days ago

      That’s been the most frustrating thing about using a password manager. I set the random generator pretty high and have to reset and decrease it randomly until the login works.

  • candyman337@lemmy.world
    link
    fedilink
    arrow-up
    16
    ·
    1 month ago

    That means they’ve updated their password requirements and your new one is now rejected, or they reject passwords of a certain age or with a lack of account activity.

    • pelespirit@sh.itjust.works
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      1 month ago

      I’m pretty sure it was because the password was compromised. That’s what I’ve heard for a decade now.

    • coffee_tacos@mander.xyz
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      30 days ago

      They better not know whether the old password matches their new password requirements, as all they should have is the salted hash of the password, which reveals no information about the password on its own.

  • Lvxferre [he/him]@mander.xyz
    link
    fedilink
    arrow-up
    12
    ·
    edit-2
    1 month ago

    I hate poorly made security/identity systems in general, but by far the worst is poorly made 2FA.

    No, I’m not giving you my number; and if using your site requires it, I’m probably giving up using your site. Ask my email and I’ll provide my burner account.

  • Thorry@feddit.org
    link
    fedilink
    arrow-up
    8
    ·
    1 month ago

    That’s because you’ve been rate limited trying passwords for an hour. When an attacker is randomly trying incorrect passwords, even the correct password will be rejected. Otherwise the protection wouldn’t be very useful.

    • BlueMagma@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      30 days ago

      To be able to display this error message and force you to use a different password, that way you won’t remember it.

  • Rhaedas@fedia.io
    link
    fedilink
    arrow-up
    5
    ·
    1 month ago

    I’ve always thought that the best password security possible would be to always have the real password fail a few times. People who know their password will keep trying it, someone else will try a different one. It’s a variation of not giving an error that tells what failed.

  • purplemonkeymad@programming.dev
    link
    fedilink
    arrow-up
    8
    arrow-down
    3
    ·
    1 month ago

    They keep multiple old passwords. You’ve done this whole stick before and you tried to use that same password last time. You use it for everything, and every time your new account gets “hacked.” You keep using that password even when we show you that it’s been in multiple leeks and is associated with your email.

    “But I like the password, it’s my favourite football team!”

  • diptchip@lemmy.world
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    edit-2
    1 month ago

    I’m more pissed that they are keeping all my old passwords… So when they get leaked, they all get leaked. Meanwhile, all our phones have cameras but we can’t have them take a pic on the wrong pin entered because why? No logic in Emailing the picture to you. That’s just silly.